Courseiva

GCFA File System Timeline Artifact Analysis Practice Question

An analyst is using The Sleuth Kit to analyze an NTFS image. They run `fls -r -m C:/` to generate a body file and then `mactime -b bodyfile -d` to produce a timeline. They notice that the timeline includes entries for files with a '$' prefix, such as $MFT, $LogFile, and $Bitmap. What is the most appropriate action for the analyst to take regarding these entries?

⚠ Common exam trap

The trap here is assuming that system files are irrelevant noise and should be filtered out, when in fact they contain important metadata for timeline analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Include them in the timeline and analyze their timestamps as they can provide evidence of file system activity and potential anti-forensic actions.

NTFS system files such as $MFT, $LogFile, and $Bitmap are essential components of the file system and their timestamps can provide critical evidence. They should be included in the timeline because they can show file system events, such as when the MFT was last written or when the log file was updated, which may correlate with user activity or anti-forensic actions. Excluding them would omit valuable data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Include them in the timeline and analyze their timestamps as they can provide evidence of file system activity and potential anti-forensic actions.

    Why this is correct

    System files such as $MFT, $LogFile, and $Bitmap are integral to the NTFS file system and their timestamps can reveal significant events, such as when the MFT was last modified, when the log file was written, or when the volume bitmap was changed. These can indicate file system activity, including potential anti-forensic actions like timestomping or wiping. Including them in the timeline is essential for a comprehensive analysis.

  • ✗

    Convert them to a separate timeline using a different tool because The Sleuth Kit cannot correctly interpret their timestamps.

    Why it's wrong here

    The Sleuth Kit is fully capable of interpreting the timestamps of NTFS system files. Tools like `fls` and `istat` can parse the $MFT and other metadata files accurately. There is no need to use a different tool; the timestamps are correctly extracted. Converting to a separate timeline would be unnecessary and could complicate the analysis. Analysts should trust TSK's output for these files.

  • ✗

    Immediately report them as indicators of compromise because their presence in the timeline suggests unauthorized access.

    Why it's wrong here

    The presence of system files like $MFT in a timeline is normal and expected; they are part of every NTFS volume. Their appearance does not indicate unauthorized access or compromise. Reporting them as indicators of compromise would be incorrect and could lead to false positives. Analysts should understand that these files are always present and their timestamps are relevant for analysis, not immediate red flags.

  • ✗

    Exclude them from the timeline because they are system files and not relevant to user activity.

    Why it's wrong here

    Excluding system files like $MFT and $LogFile would remove critical metadata that can provide valuable context for timeline analysis. These files contain information about file system structure and activity, and their timestamps can indicate when the file system was last modified or when certain operations occurred. They should not be automatically excluded; instead, they should be analyzed with an understanding of their role.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.